CVE-2025-6019: Red Hat Enterprise Linux 10

High severity, CVSS 7.0. EPSS: 0.5% chance of exploitation in the next 30 days.

A Local Privilege Escalation (LPE) vulnerability was found in libblockdev. Generally, the "allow_active" setting in Polkit permits a physically present user to take certain actions based on the session type. Due to the way libblockdev interacts with the udisks daemon, an "allow_active" user on a system may be able escalate to full root privileges on the target host. Normally, udisks mounts user-provided filesystem images with security flags like nosuid and nodev to prevent privilege escalation. However, a local attacker can create a specially crafted XFS image containing a SUID-root shell, then trick udisks into resizing it. This mounts their malicious filesystem with root privileges, allowing them to execute their SUID-root shell and gain complete control of the system.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 0:3.2.0-4.el10_0 (fixed in 0:3.2.0-4.el10_0)
  • Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:2.18-5.el7_9.1 (fixed in 0:2.18-5.el7_9.1)
  • Red Hat Red Hat Enterprise Linux 8: before 0:2.28-7.el8_10 (fixed in 0:2.28-7.el8_10)
  • Red Hat Red Hat Enterprise Linux 8.2 Advanced Update Support: before 0:2.19-13.el8_2 (fixed in 0:2.19-13.el8_2)
  • Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:2.24-6.el8_4 (fixed in 0:2.24-6.el8_4)
  • Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:2.24-9.el8_6 (fixed in 0:2.24-9.el8_6)
  • Red Hat Red Hat Enterprise Linux 8.6 Telecommunications Update Service: before 0:2.24-9.el8_6 (fixed in 0:2.24-9.el8_6)
  • Red Hat Red Hat Enterprise Linux 8.6 Update Services For SAP Solutions: before 0:2.24-9.el8_6 (fixed in 0:2.24-9.el8_6)
  • Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:2.28-3.el8_8 (fixed in 0:2.28-3.el8_8)
  • Red Hat Red Hat Enterprise Linux 9: before 0:2.28-14.el9_6 (fixed in 0:2.28-14.el9_6)
  • Red Hat Red Hat Enterprise Linux 9.0 Update Services For SAP Solutions: before 0:2.25-12.el9_0 (fixed in 0:2.25-12.el9_0)
  • Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:2.28-5.el9_2 (fixed in 0:2.28-5.el9_2)
  • Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 0:2.28-11.el9_4 (fixed in 0:2.28-11.el9_4)

Published 2025-06-19. Last modified 2026-06-30.